Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to DevSecOps and the ECDE Framework
- Core fundamentals and principles of DevSecOps
- Key security challenges within DevOps environments
- Overview of the ECDE examination structure and domains
Fostering a Secure DevOps Culture and Mindset
- Embracing security as a collective responsibility
- Shifting security left within the SDLC
- Aligning stakeholders and defining team roles
Incorporating Security into CI/CD Pipelines
- Hardening pipelines in Jenkins, GitLab CI, and Azure DevOps
- Managing secrets and configuring environments securely
- Executing secure container builds and image scanning
Application Security within DevSecOps
- Utilizing Static and Dynamic Application Security Testing (SAST/DAST)
- Scanning open-source dependencies using SCA tools
- Conducting secure code reviews and adopting secure coding practices
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes
- Implementing Identity and Access Management (IAM) and policy-as-code
- Applying DevSecOps in hybrid and multi-cloud setups
Monitoring, Compliance, and Incident Readiness
- Establishing security monitoring and logging within CI/CD
- Automating compliance with standards such as NIST, ISO, and SOC 2
- Streamlining automated remediation and incident response workflows
ECDE Exam Preparation and Final Lab
- Understanding the ECDE exam format and preparation strategies
- Completing a capstone DevSecOps pipeline lab
- Undergoing knowledge checks and readiness assessments
Summary and Next Steps
Requirements
- Foundational knowledge of DevOps workflows and tools
- Familiarity with the software development lifecycle (SDLC)
- Background knowledge in application security principles is advantageous
Target Audience
- DevOps engineers
- Application security specialists
- Software developers tasked with integrating security into their pipelines
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated